Close Menu
  • Latest News
    • Bitcoin
    • Ethereum
    • Altcoins
    • Meme Coins
  • DeFi
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • Gaming
  • Legal
    • Taxes & Regulation
    • Adoption
  • Analysis
  • Learn
    • Education
    • Wallets and Exchanges
  • Tools
    • Market Overview
    • Converter
What's Hot

The Three Main Approaches and Their Pros and Cons

August 24, 2025

UltraVizion Antenna Delivers Free HD and 4K Channels in 2025 Without Monthly Bills

August 24, 2025

TradeOS Taps Revox AI to Redefine Web3 with AI-to-AI Composability

August 24, 2025
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
  • Disclosure
Facebook X (Twitter) Instagram
Buy Crypto NewsBuy Crypto News
  • Latest News
    1. Bitcoin
    2. Ethereum
    3. Altcoins
    4. Meme Coins
    5. View All

    The Three Main Approaches and Their Pros and Cons

    August 24, 2025

    Fed Chair Powell Sparks $300M Surge in Binance BTC Futures

    August 24, 2025

    KPMG Sees Strong Second Half for Canadian Fintechs After Crypto, AI Raked in $1.6B Funding

    August 24, 2025

    Inside Costa Rica’s Growing Bitcoin Circular Economy

    August 23, 2025

    Ethereum eyes historic highs amid mixed institutional signals: What’s next?

    August 24, 2025

    ETC Price Breaks Out of Downtrend as Momentum Builds Toward $26

    August 24, 2025

    Ethereum Open Interest Jumps 10% As $3.18B In New Positions Flood In

    August 23, 2025

    Whales take $16 mln ETH to Bitcoin, yet Ethereum remains strong

    August 23, 2025

    VanEck’s JitoSOL ETF: A game-changer for Solana DeFi adoption?

    August 24, 2025

    Chainlink Eyes Fresh Upside As Oversold Bounce Sets Stage For Bullish Continuation

    August 24, 2025

    Arbitrum price prediction: What are 2 factors behind ARB’s next move?

    August 23, 2025

    Crypto Fear and Greed Index Surges as Powell Speech Sparks Bullish Wave

    August 23, 2025

    Pepe, BMT, CAKE: Crypto Activity Heats Up

    March 18, 2025

    SHIB Burns Over Half a Billion Tokens, Price Surges Over 7%

    March 17, 2025

    DOGE Sees Massive User Growth: Active Addresses Up 400%

    March 15, 2025

    Shiba Inu (SHIB) Price Analysis: Bullish Hints, Bearish Trend

    March 15, 2025

    The Three Main Approaches and Their Pros and Cons

    August 24, 2025

    UltraVizion Antenna Delivers Free HD and 4K Channels in 2025 Without Monthly Bills

    August 24, 2025

    TradeOS Taps Revox AI to Redefine Web3 with AI-to-AI Composability

    August 24, 2025

    Kroll faces class-action suit as FTX creditors allege daily scam emails

    August 24, 2025
  • DeFi

    Morpho price set for a 60% jump as top metrics hit record highs

    August 24, 2025

    Hyperliquid Grabs 80% of Perp DEX Market in One Year, Analysts Say

    August 24, 2025

    Private DeFi is also about market efficiency

    August 23, 2025

    Why Wall Street’s old guard still won’t touch crypto

    August 23, 2025

    Ensemble integrates XMTP to bring AI Agents to decentralised messaging

    August 23, 2025
  • Tech
    1. Blockchain
    2. Security and Privacy
    3. View All

    TradeOS Taps Revox AI to Redefine Web3 with AI-to-AI Composability

    August 24, 2025

    Scammer Poses as UK Police Chief to Steal $2.8M Bitcoin Through Phishing Attack

    August 24, 2025

    0G Labs Rolls Out Chinese-Language Bootcamps to Onboard 3,000 Developers

    August 24, 2025

    EU Explores Ethereum or Solana for Digital Euro as US Stablecoin Law Raises Pressure: Report

    August 24, 2025

    TRM Launches Industry-Wide Platform to Fight Crypto Crimes

    August 21, 2025

    USB Malware Campaign Spreads Cryptominer Worldwide

    August 19, 2025

    Embargo Ransomware Gang Amasses $34.2m in Attack Proceeds

    August 11, 2025

    Fake Ethereum trading bots on YouTube help scammers steal over $900K

    August 7, 2025

    The Three Main Approaches and Their Pros and Cons

    August 24, 2025

    UltraVizion Antenna Delivers Free HD and 4K Channels in 2025 Without Monthly Bills

    August 24, 2025

    TradeOS Taps Revox AI to Redefine Web3 with AI-to-AI Composability

    August 24, 2025

    Kroll faces class-action suit as FTX creditors allege daily scam emails

    August 24, 2025
  • Web 3
    1. Web3 News
    2. Gaming
    3. View All

    UltraVizion Antenna Delivers Free HD and 4K Channels in 2025 Without Monthly Bills

    August 24, 2025

    FED Fitness Expands Its Amazon Best Seller Lineup: Shaping the Future of Home Fitness for Quality-Focused Families

    August 24, 2025

    Drivio Play Offers Affordable Car Tech Upgrade in 2025: Portable Infotainment System Brings Navigation, Streaming, and Hands-Free Safety Features to Older Vehicles

    August 24, 2025

    How to Master Domain Valuation: Expert Methods That Actually Work

    August 23, 2025

    Crypto Gaming Handheld Shipments Delayed Over ‘Excessive’ Import Duties

    August 23, 2025

    Why AI NFT Companion Coins Could Be the Key to NFT Market Revival

    August 22, 2025

    Immutable & Koin Games Unveil Fast-Paced, Collector-Driven Project O

    August 21, 2025

    Wilder World Launches FPS at Gamescom with Samsung Partnership and $100K Prize Pool

    August 20, 2025

    The Three Main Approaches and Their Pros and Cons

    August 24, 2025

    UltraVizion Antenna Delivers Free HD and 4K Channels in 2025 Without Monthly Bills

    August 24, 2025

    TradeOS Taps Revox AI to Redefine Web3 with AI-to-AI Composability

    August 24, 2025

    Kroll faces class-action suit as FTX creditors allege daily scam emails

    August 24, 2025
  • Legal
    1. Taxes & Regulation
    2. Adoption
    3. View All

    Kroll faces class-action suit as FTX creditors allege daily scam emails

    August 24, 2025

    LIBRA Soars 400% as $57M USDC Gets Unfrozen by Court

    August 24, 2025

    Assistant Attorney General Galeotti’s Talk Changes Very Little

    August 23, 2025

    CFTC Opens Next Phase of Crypto Sprint, Seeks Public Input on Broader Rules

    August 23, 2025

    Ethereum breaks above 2021 all-time high after blistering 15% rally

    August 23, 2025

    Philippines lawmaker introduces legislation to acquire 10,000 Bitcoin for national security reserve

    August 23, 2025

    Digital euro may launch on Ethereum or Solana as Brussels scrambles for sovereignty

    August 22, 2025

    State Street issues $100M digital debt securities on JPMorgan’s proprietary blockchain

    August 22, 2025

    The Three Main Approaches and Their Pros and Cons

    August 24, 2025

    UltraVizion Antenna Delivers Free HD and 4K Channels in 2025 Without Monthly Bills

    August 24, 2025

    TradeOS Taps Revox AI to Redefine Web3 with AI-to-AI Composability

    August 24, 2025

    Kroll faces class-action suit as FTX creditors allege daily scam emails

    August 24, 2025
  • Analysis

    SharpLink to buy back $1.5 billion in stock as Ethereum price climbs

    August 23, 2025

    AAVE Price Surges 30% as Collaborations & Fed Rate-Cut Hopes Fuel Momentum

    August 23, 2025

    Can ARB Sustain Its Momentum After 18% Jump?

    August 23, 2025

    MEME Price Soars 64% in 24 Hours as ETF Hype Lifts Memecoins

    August 23, 2025

    Ethereum Price Almost Hit ATH as Fed Chair Signals Rate Cut

    August 23, 2025
  • Learn
    1. Education
    2. Wallets and Exchanges
    3. View All

    What Is Grok AI? Elon Musk’s Controversial ChatGPT Rival

    August 11, 2025

    What Is Tokenization?

    July 11, 2025

    What Are Internet Capital Markets? Why Companies Are Launching Meme Coins

    June 16, 2025

    What is a Corporate Bitcoin Treasury? The Strategy Behind Companies Holding Crypto

    May 27, 2025

    Binance volume surpasses top 5 competitors combined as crypto markets contract

    August 22, 2025

    Kraken and Backed Announce Strategic Collaboration with TRON DAO to Broaden Access to Tokenized Equities

    August 21, 2025

    Ripple’s RLUSD gains institutional traction in Bullish IPO settlement

    August 20, 2025

    Gemini IPO filing reveals Ripple credit deal, $282M net loss in 2025

    August 19, 2025

    The Three Main Approaches and Their Pros and Cons

    August 24, 2025

    UltraVizion Antenna Delivers Free HD and 4K Channels in 2025 Without Monthly Bills

    August 24, 2025

    TradeOS Taps Revox AI to Redefine Web3 with AI-to-AI Composability

    August 24, 2025

    Kroll faces class-action suit as FTX creditors allege daily scam emails

    August 24, 2025
  • Tools
    • Market Overview
    • Converter
Buy Crypto NewsBuy Crypto News
Home»Security and Privacy»XRP Ledger developer kit compromised with backdoor to steal wallet private keys
XRP Ledger developer kit compromised with backdoor to steal wallet private keys
Security and Privacy

XRP Ledger developer kit compromised with backdoor to steal wallet private keys

April 23, 2025No Comments2 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

Aikido Security recently uncovered a critical vulnerability in the XRP Ledger’s official JavaScript SDK, raising concerns about compromised versions of the XRPL Node Package Manager (NPM) package that were published to the registry starting April 21.

The affected versions, specifically v4.2.1 through v4.2.4 and v2.14.2, were found to contain a backdoor that could potentially exfiltrate private keys, posing a significant threat to crypto wallets relying on the software.

NPM packages serve as reusable modules for JavaScript and Node.js projects, simplifying the installation, updates, and removal processes. Aikido Security’s automated threat monitoring platform detected the anomaly when NPM user “mukulljangid” released five new versions of the XRPL package that did not align with any tagged releases on the official GitHub repository, triggering suspicions of a supply chain compromise.

Further analysis revealed that the compromised packages included a function called checkValidityOfSeed, which made external calls to the unverified domain 0x9c[.]xyz. This function, triggered during the wallet class instantiation, surreptitiously transmitted private keys during wallet creation.

Initially, the malicious code was embedded in the built JavaScript files of early versions (v4.2.1 and v4.2.2). Subsequent iterations (v4.2.3 and v4.2.4) introduced the backdoor into the TypeScript source files, which were then compiled into production code. The attacker’s tactics evolved from manual JavaScript manipulation to more sophisticated integration into the SDK’s build process.

This targeted attack against the crypto development infrastructure impacted hundreds of thousands of applications and websites utilizing the compromised XRPL package. The compromised versions also removed development tools and scripts from the package.json file, indicating deliberate tampering.

In response to the security vulnerability, the XRP Ledger Foundation promptly acknowledged the issue and initiated efforts to address the issue. The Foundation removed the affected versions from the NPM registry following the disclosure. However, the extent to which users had integrated the compromised versions before the issue was identified remains uncertain.

See also  XRP Price Crashes Hard: Is There a Recovery in Sight?

Mark Ibanez, CTO of XRP Ledger-based Gen3 Games, highlighted the importance of best practices to mitigate risks, such as committing the “lockfile” to version control, utilizing Performant NPM (PNPM) when feasible, and avoiding unintended version upgrades by refraining from using the caret (^) symbol in package.json.

The XRP Ledger Foundation’s commitment to resolving the security issue underscores the ongoing efforts to safeguard the integrity of the XRPL ecosystem and protect users from potential threats.

Backdoor Compromised Developer Keys Kit Ledger Private Steal wallet XRP
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Scammer Poses as UK Police Chief to Steal $2.8M Bitcoin Through Phishing Attack

August 24, 2025

Private DeFi is also about market efficiency

August 23, 2025

Will XRP price rally on Gemini XRP Mastercard launch?

August 22, 2025

What Next for ETH, XRP, SOL as BTC Price Stalls at $113K, ETF Outflows Mount

August 22, 2025
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Nasdaq Tells SEC Precise Crypto Labeling Will Be Everything in Future Regulation

April 27, 2025

Binance warns of crypto fraud

December 22, 2024

US financial giants Bank of America look to enter stablecoin market as PayPal advances PYUSD

February 27, 2025
Price Chart


Explore insights on crypto, blockchain, taxes, and security. Stay informed with expert guides, tips, and the latest trends to navigate the digital asset world confidently


We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

The Three Main Approaches and Their Pros and Cons

August 24, 2025

UltraVizion Antenna Delivers Free HD and 4K Channels in 2025 Without Monthly Bills

August 24, 2025

TradeOS Taps Revox AI to Redefine Web3 with AI-to-AI Composability

August 24, 2025
Get Informed

Subscribe to Updates

Get the latest creative news From BuyCryptoNews directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
  • Disclosure
© 2025 BuyCryptoNews - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.